package dao;

import java.sql.Connection;
import java.sql.ResultSet;
import java.sql.Statement;

public class UserDao {

    User user ;
    private String SQL =""; 
    public User login(String username, String password){
        SQL = "select * from login where username ='"+username+"' and password ='"+password+"'";
        Connection connection=null ;
        Statement stmt ;
        try {
            connection = DBcon.getConnection();
            stmt = connection.createStatement();
            ResultSet rs =  stmt.executeQuery(SQL);
            if(rs.next()){
                user = new User();
                user.setUsername(rs.getString("username"));
                user.setPassword(rs.getString("password"));
            }
            rs.close();
            stmt.close();
        } catch (Exception e) {
            // TODO: handle exception
            e.printStackTrace();
        }finally{
            DBcon.closeConnection(connection);
        }
        return user;
    }

}
